Vulnerabilities
Vulnerable Software
Moxa:  Security Vulnerabilities
Memory leak on Moxa Secure Router EDR-G903 devices before 3.4.12 allows remote attackers to cause a denial of service (memory consumption) by executing the ping function.
CVSS Score
7.5
EPSS Score
0.007
Published
2016-05-31
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to discover cleartext passwords by reading a configuration file.
CVSS Score
7.5
EPSS Score
0.004
Published
2016-05-31
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to read configuration and log files via a crafted URL.
CVSS Score
7.5
EPSS Score
0.008
Published
2016-05-31
Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt data, which makes it easier for remote attackers to obtain the associated cleartext via unspecified vectors.
CVSS Score
5.3
EPSS Score
0.004
Published
2016-03-04
Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt credentials, which makes it easier for remote attackers to obtain the associated cleartext via unspecified vectors.
CVSS Score
5.3
EPSS Score
0.006
Published
2016-03-04
The login function in the RequestController class in Moxa OnCell Central Manager before 2.2 has a hardcoded root password, which allows remote attackers to obtain administrative access via a login session.
CVSS Score
8.3
EPSS Score
0.002
Published
2015-12-21
The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain administrative access via a command, as demonstrated by the addUserAndGroup action.
CVSS Score
8.3
EPSS Score
0.002
Published
2015-12-21
Cross-site scripting (XSS) vulnerability in the Diagnosis Ping feature in the administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote attackers to inject arbitrary web script or HTML via an unspecified field.
CVSS Score
4.3
EPSS Score
0.011
Published
2015-09-11
The GoAhead web server on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authenticated users to cause a denial of service (reboot) via a crafted URL.
CVSS Score
6.8
EPSS Score
0.011
Published
2015-09-11
The administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authenticated users to bypass a read-only protection mechanism by using Firefox with a web-developer plugin.
CVSS Score
8.5
EPSS Score
0.002
Published
2015-09-11


Contact Us

Shodan ® - All rights reserved